Let's see. SMF 1.1 has had 13 post-final patches, which are all security related. That's in 5 years.
Just take a look through
http://wordpress.org/news/category/releases/ and see how many of the patches were security related.
To be fair, even with SMF 2.0's long life cycle, the team were pretty prompt about getting security patches out. There are vulnerabilities in RC2 (patchwise, equivalent to 1.1.11), some in RC3/4 (equivalent to 1.1.13), and let's not forget the vulns that were fixed as 2.0 RC1-1 and 2.0 RC1.2 (1.1.9 and 1.1.10 respectively)
I still say SMF and by proxy Wedge have a better track record of security that WP does. And before anyone gives me the crap of 'it's a bigger target', WP is a simpler application than SMF is, so by definition it should be safer - and yet...